This notice is part of the Cutvey Privacy Policy. It explains the cookies and similar technologies Cutvey LLC uses, by category and purpose, across our web app, our marketing and product websites, our native apps and our email.
We have kept this short because there is very little to report. Cutvey puts no advertising cookies, no third-party analytics cookies and no cross-site tracking on any page we build, anywhere. That is a product decision, not a temporary state. A studio can embed something of its own choosing in a page it sends to its own client, and section 1 says what that means.
Strictly necessary cookies only. Without them the app cannot sign you in or keep you safe.
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| Session cookie | Keeps you signed in to your workspace. Signed, HTTP-only, and revocable from Settings | Strictly necessary, first party | Until you sign out, or the session expires |
| Sign-in and device cookie | Remembers a device you marked as trusted, so you are not asked for a code every time | Strictly necessary, first party | Until you revoke the device |
| Security and anti-abuse cookie | Cross-site request forgery protection and rate limiting, and preventing repeat free trials. For the last of these, a browser that starts a free trial of the Service is given a random identifier (cutvey_tb). It holds nothing about you, it is HTTP-only, and it is never sent to anyone else. It is not set for visitors we believe to be in the European Economic Area, the United Kingdom or Switzerland | Strictly necessary, first party | Session, or short-lived. The free trial identifier is kept for up to 2 years |
| Preference storage | Remembers a choice you made in the app, such as the theme you picked or the view you last used. Kept in your browser's local storage, not sent to our servers. We store it only because you chose it, and storing it is the only way to give you what you asked for | Strictly necessary, first party | Until you clear your browser data |
| Bot-protection token on the signup form | Set by Cloudflare, Inc. (Turnstile) on our behalf, on the form where you create a Cutvey account, to confirm that a human, not a script, is signing up. The same check, on the same terms, as on the forms described in section 2 | Strictly necessary, third party, for security | Minutes, tied to the form submission |
Referral record (cutvey_ref) | Set only when you arrive through another workspace's referral link. It holds that link's referral code and nothing about you, so that if you sign up we can give you the longer free trial the link offers and credit the workspace that referred you. HTTP-only, so no script on the page can read it | First party, set only because you followed the link | 30 days |
Privacy signal record (cutvey_gpc) | Set only when your browser sends the Global Privacy Control signal. It holds the value 1 and nothing else, and it exists so that we count your signal once rather than on every page. Section 18 of the Privacy Policy says what we do with the signal | Strictly necessary, first party, a record of a choice you made | One year |
These are strictly necessary to deliver the service you asked for. Under the EU ePrivacy rules and the UK Privacy and Electronic Communications Regulations they do not require consent, which is why you do not see a cookie consent banner in the app.
We class nothing as strictly necessary that we would not defend as strictly necessary. Everything above is either what signs you in, what keeps the app safe, or what remembers a choice you actively made. If we ever store or read anything on your device for another reason, including measurement, we will ask you first and give you a way to change your answer.
Video in a page a studio sends you. Cutvey's own video player is served from our own systems and reports to nobody but us, and we put no third party pixel, tag or software development kit on a page where Cutvey plays video. A studio can also paste a link to a video hosted somewhere else, for example on a video sharing site, into a proposal or another page it sends you. Where it does, the page shows you a still image and the name of the company whose player it is, and that player loads only after you choose to play it. Until you do, nothing about you reaches that company and it sets nothing on your device. When you press play, that company sees the request and can set its own cookies under its own privacy policy and terms. That player is the studio's choice, not ours. We do not choose those sites, we send them nothing about you, and we receive nothing back.
Our public websites are cutvey.com, cutveyoffload.com, cutveymeter.com, cutveyviewfinder.com, cutveyteleprompter.com and cutveysetrush.com, all listed at https://cutvey.com/legal. They set no analytics cookies, no advertising cookies and no third-party tracking of any kind. We put no advertising or analytics pixel, tag or software development kit on any page. We do not use Google Analytics, Meta pixels, LinkedIn Insight, TikTok pixels or anything comparable.
The only cookies you may meet come from the infrastructure that keeps the sites up and keeps bots off our forms:
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| Bot-protection token | Cloudflare, Inc. (Turnstile), on our behalf | Confirms that a human, not a bot, is submitting a contact, support or lead form. Cloudflare states that Turnstile does not use this data for advertising and does not track users across sites. We do not receive an advertising profile or a cross-site identifier from it, and we would not use one | Minutes, tied to the form submission |
Infrastructure cookie (for example __cf_bm) | Cloudflare, Inc. | Tells human traffic from automated traffic so the site stays available. Strictly necessary for security | Up to 30 minutes |
Lead forms in a studio's client portal. A studio's own lead-capture form, served through Cutvey, is protected the same way, using that studio's own configured keys. The studio is the controller of what the form collects.
This section applies to every Cutvey native application, current and future. The Privacy Policy's product table lists them.
Native apps do not use cookies. They store what they need on your device and, where you turn it on, in your own iCloud. In practice what an app keeps on the device is some of: your settings, your own content, a sign-in token if you signed in, the record of the analytics answer you gave on first run, and a cache of what you last worked on. Each App's row in section 4 of the Privacy Policy says which of these apply to it. None of it is shared with anyone else, and deleting the app removes it from the device. Apps contain no advertising SDKs, no attribution SDKs and no cross-site or cross-app tracking technology. No app contains a third party crash reporting or analytics component. Crash and diagnostic reports go to an endpoint we operate, and we forward them from our own servers to the provider named on our subprocessor list, which may use them only to provide that service to us.
Usage data and crash reports in the apps follow section 8 of the Privacy Policy. Optional usage data and crash reports are on by default where the law allows a default. In the European Economic Area, the United Kingdom, Switzerland, throughout Canada, anywhere else whose law requires your agreement before an app reads or stores this kind of information on your device, and wherever we cannot tell which of these you are in, every app asks you on first run and collects nothing until you agree. Wherever you are, you can change the answer at any time in the App's Settings. Because there is no advertising or attribution technology in any app, you do not see an App Tracking Transparency prompt. The permission we ask for is about improving our own software, not about following you anywhere else.
Our own email to you. Sign-in codes, receipts, invoices, notifications and security alerts record only delivery and bounce events, because we need to know the message arrived. They carry no tracking pixel.
Our product announcements do record opens and link clicks, so we can tell whether an announcement was worth sending. Measuring an open means loading a small image from our servers, which counts as access to your device under European and UK rules. So we ask for your agreement to that measurement when you subscribe, if you are in the European Economic Area, the United Kingdom or Switzerland. We do not measure opens for anyone who has not agreed. To withdraw, use the preference link in any announcement, or email [email protected]. We record your answer against your email address and apply it to every later message. Every announcement also carries a one-click unsubscribe.
Email a studio sends through Cutvey. A proposal, invoice, call sheet or gallery link that a studio sends to its own client can carry a small tracking image and click-tracked links, so the studio can tell whether the client opened it. The studio decides whether to use tracking and on whom. Our Terms require the studio to disclose it to recipients where its law requires, and to honor a recipient who asks to be emailed without tracking. We build and host the measurement, we secure the data, and we provide the off switch. Every workspace can turn tracking off for all of its outgoing mail in Settings, off for a single message when it is sent, and off for an individual recipient who asks. The engagement data stays in the studio's workspace and we never use it for our own marketing.
If you received such an email and do not want the open counted, most email clients can block remote images, which stops the image from loading. Blocking images does not affect link clicks: if you click a link in the message, the sender can still see that you did. To stop it entirely, ask the studio that sent it.
You can delete or block cookies in your browser settings. Blocking the strictly necessary cookies in section 1 stops you from signing in to the app, which is the whole of what they do.
Because we set nothing beyond strictly necessary on the web, there is no consent preference for you to manage there and no "reject non-essential cookies" button to press. Our native apps are different: where the law requires it they ask you on first run about usage data and crash reporting, because that involves reading information from your device, and wherever you are you control the answer in the App's Settings. If the web app ever needs the same question asked, we will ask it there too.
We update this notice whenever the technologies we use change, and the "Last updated" date above tells you when. Material changes are notified as described in section 20 of the Privacy Policy. When this notice changes, the version it replaces will be kept at https://cutvey.com/legal/archive. How we number versions, and what counts as a change to a table row rather than to this document, is set out in section 20 of the Privacy Policy and applies to every Cutvey legal document.
Questions: [email protected].